MGASA-2020-0146 - Updated sympa packages fix security vulnerability

Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0146.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2020-9369

Updated sympa packages fix security vulnerability:

Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial
of service (disk consumption from temporary files, and a flood of
notifications to listmasters) via a series of requests with malformed
parameters (CVE-2020-9369).

References:
- https://bugs.mageia.org/show_bug.cgi?id=26308
- https://www.sympa.community/security/2020-001.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9369

SRPMS:
- 7/core/sympa-6.2.42-1.1.mga7

Mageia 2020-0146: sympa security update

Updated sympa packages fix security vulnerability: Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a f...

Summary

Updated sympa packages fix security vulnerability:
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters (CVE-2020-9369).

References

- https://bugs.mageia.org/show_bug.cgi?id=26308

- https://www.sympa.community/security/2020-001.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-9369

Resolution

MGASA-2020-0146 - Updated sympa packages fix security vulnerability

SRPMS

- 7/core/sympa-6.2.42-1.1.mga7

Severity
Publication date: 01 Apr 2020
URL: https://advisories.mageia.org/MGASA-2020-0146.html
Type: security
CVE: CVE-2020-9369

Related News